A comprehensive cybersecurity protection system and method for ships
By classifying and processing ship computer systems and dividing network security zones, configuring firewall policies and data exchange channels, and implementing encryption authentication and intelligent optimization algorithms, the problem of mismatched ship network security protection policies has been solved, achieving real-time response and precise network security protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-12
- Publication Date
- 2026-03-06
AI Technical Summary
Existing ship cybersecurity protection strategies cannot detect changes in cyber threats in real time, resulting in mismatched protection strategies and delayed responses, and failing to guarantee the accuracy and real-time nature of cybersecurity protection.
By collecting and classifying data from ship computer systems, system classification data is generated, network security zones are divided, firewall policies and network access control are configured, dedicated data exchange channels are established and encrypted authentication is implemented, a dynamic threat assessment matrix is constructed, intelligent optimization algorithms are used to match the optimal security protection strategy, a network security status assessment report is generated, and the protection strategy is dynamically adjusted.
It enables real-time response and dynamic adjustment of ship network security, improves the accuracy and continuous improvement capabilities of network security protection, enhances access control capabilities and data transmission reliability, and reduces the risk of network attacks.
Smart Images

Figure CN121309230B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of ship network communication technology, specifically to a comprehensive ship network security protection system and method. Background Technology
[0002] In recent years, with the widespread use of technologies such as remote monitoring, automatic control, the Internet of Things and digitalization in ships, the interconnection of shipboard computer systems, and the widespread promotion of ship-to-shore communication, ships have become more vulnerable to cyberattacks, and the consequences of such attacks are more severe. Regardless of whether the shipboard computer system has a network connection or any other interface with the outside world, attackers can exploit any combination of human and technological vulnerabilities to achieve their attack targets.
[0003] Currently, due to the integration of multiple computer systems in ship network systems and frequent ship-to-shore communication, existing static protection strategies cannot detect changes in network threats in real time and dynamically adjust protection measures when conducting comprehensive ship network security protection. If new or complex network attacks are encountered, it may lead to mismatched protection strategies and delayed response, failing to guarantee the accuracy and real-time nature of network security protection.
[0004] Therefore, a comprehensive ship network security protection system and method are proposed to solve the above problems. Summary of the Invention
[0005] To address the shortcomings of existing technologies, this invention provides a comprehensive ship network security protection system and method, which solves the problems of mismatched protection strategies, delayed response, and inability to guarantee the accuracy and real-time performance of network security protection mentioned in the background technology.
[0006] To achieve the above objectives, the present invention provides the following technical solution: a comprehensive ship network security protection system and method, the method comprising:
[0007] S1. Collect data from the ship's computer system and classify it to generate system classification data;
[0008] S2. Based on the system classification data, perform network security zone division processing to generate security zone division data;
[0009] S3. Based on the security zone division data, perform boundary protection deployment processing, configure firewall policies and network access control mechanisms, and generate boundary protection configuration data;
[0010] S4. Based on the security zone division data and boundary protection configuration data, and combined with the characteristics of ship network communication needs, establish a dedicated data exchange channel and implement data transmission encryption authentication to generate data exchange channel data;
[0011] S5. Obtain current network security status information through real-time network traffic monitoring, construct a dynamic threat assessment matrix based on security zone division data, boundary protection configuration data and data exchange channel data, and use intelligent optimization algorithms to match the optimal security protection strategy to generate target security protection algorithm data.
[0012] S6. Integrate the security zone division data, boundary protection configuration data, data exchange channel data, and target security protection algorithm data, and perform full lifecycle network security protection operations through the ship network monitoring platform to generate a network security status assessment report;
[0013] S7. Analyze the effectiveness of the protection strategy based on the network security status assessment report, dynamically adjust the boundary protection strategy and data exchange channel parameters, generate optimized protection strategy data, and update it to the ship network monitoring platform.
[0014] Preferably, the process of collecting and classifying ship computer system data includes the following steps:
[0015] S11. Collect functional parameters of the ship's computer system through the ship network monitoring platform, including system name, function description, communication protocol type and physical location information;
[0016] S12. Classify ship computer systems according to the standards of the International Association of Classification Societies (IACS), dividing the systems into categories such as safety systems, communication and navigation systems, mechanical systems, engineering operation systems, cargo management systems, ship office management systems, crew and passenger entertainment systems, and wireless communication equipment, and generate system classification data.
[0017] S13. Standardize the system classification data and encode it to ensure that each system category has a unique identifier.
[0018] Preferably, the network security zone division process includes the following steps:
[0019] S21. Obtain the system classification data and combine it with the ship's physical space distribution information, including the deck area, engine room area, bridge, and crew living area, to make a preliminary division of network security areas;
[0020] S22. In accordance with the unified requirements of international classification societies, the initially defined areas will be further refined:
[0021] Safety system equipment is separately classified into the ship safety system area; communication and navigation system equipment is classified into the ship communication and navigation system area; mechanical system equipment is classified into the ship mechanical system area; engineering operation and cargo management equipment is classified into the cargo and engineering system area; wireless communication equipment is classified into the wireless equipment area; office management systems are classified into the management system area; and entertainment systems and uncertified systems are classified into other network areas.
[0022] S23. Generate security zone division data, including zone number, zone name, list of applicable systems and physical boundary description.
[0023] Preferably, the boundary protection deployment process includes the following steps:
[0024] S31. Based on the security zone division data, deploy industrial-grade firewall devices at the boundary of each security zone and configure port-based access control policies, including prohibiting unnecessary external access, restricting communication protocol types, and monitoring data traffic.
[0025] S32. Develop software protection strategies, including regularly updating operating system patches and implementing network access control technology to authenticate and check the security status of access devices;
[0026] S33. Verify the boundary protection configuration and generate boundary protection configuration data.
[0027] Preferably, the generation of data exchange channel data includes the following steps:
[0028] S41. Based on the security zone division data and boundary protection configuration data, analyze the communication requirements between each zone, including data volume, real-time requirements and reliability indicators;
[0029] S42. Select the data exchange channel topology according to communication requirements, including star topology, ring topology and redundant tree topology, and use fiber optic communication technology and industrial Ethernet technology to construct the channel.
[0030] S43. Implement data transmission security measures, including using the AES encryption algorithm to encrypt data, establishing a two-way identity authentication mechanism based on digital certificates, and generating data exchange channel data.
[0031] Preferably, the generation of target security protection algorithm data includes the following steps:
[0032] S51. Establish a database of standard security threat patterns corresponding to different security protection algorithms, represented as a matrix:
[0033] ;
[0034] in For a matrix, Indicates the first Standard security threat pattern data corresponding to each type of security protection algorithm. This represents the maximum number of security protection algorithm types.
[0035] S52. Match the real-time collected network traffic data with the standard security threat pattern database, search for the optimal protection algorithm type through artificial intelligence optimization algorithm, and generate target security protection algorithm data.
[0036] Preferably, the artificial intelligence optimization algorithm adopts the biomimetic osprey algorithm, which specifically includes the following sub-steps:
[0037] S521. Initialize algorithm parameters, including maximum number of iterations, population size, and search space boundary;
[0038] S522, Exploration Phase: Simulate the ospreys randomly detecting the location of threat patterns, update the population location, and evaluate fitness values;
[0039] S523, Development Phase: Simulate osprey hunting behavior, calculate new locations, and optimize matching results;
[0040] S524. Iterate until the termination condition is met, and output the security protection algorithm type that best matches the real-time data.
[0041] Preferably, generating the network security status assessment report includes the following steps:
[0042] S61. Combine and encapsulate the security zone division data, boundary protection configuration data, data exchange channel data, and target security protection algorithm data to construct security protection summary data;
[0043] S62. The ship network monitoring platform calls the corresponding protection program based on the target security protection algorithm data to perform real-time monitoring and protection processing of network traffic;
[0044] S63. Generate network security status data, including threat logs, protection effectiveness assessments, and system health indicators.
[0045] Preferably, the process of generating optimized protection strategy data and updating it to the ship network monitoring platform includes the following steps:
[0046] S71. Based on the network security status data, perform protection strategy effectiveness analysis and identify weak points;
[0047] S72. Adaptive learning algorithms are used to dynamically adjust the boundary protection strategy and data exchange channel parameters;
[0048] S73. Generate optimized protection strategy data and update it to the ship network monitoring platform.
[0049] Preferably, the system includes a ship system data acquisition module, a security zone division module, a boundary protection deployment module, a data exchange channel establishment module, a security threat detection module, a protection algorithm matching module, a security protection execution module, and a strategy optimization module;
[0050] The ship system data acquisition module collects the ship computer system operating parameters through the ship network data acquisition unit and generates system classification data using the system classification processing unit.
[0051] The security zone division module receives the system classification data, determines the network security zone boundary through the zone logical division unit, and outputs the security zone division data using the zone attribute configuration unit.
[0052] The boundary protection deployment module receives the security zone division data, deploys hardware protection devices through the firewall policy configuration unit, and generates boundary protection configuration data using the security policy loading unit.
[0053] The data exchange channel establishment module receives the security zone division data and boundary protection configuration data, designs the data exchange path through the channel topology construction unit, and generates data exchange channel data using the secure transmission protocol unit.
[0054] The security threat detection module collects network data streams through a real-time traffic monitoring unit and outputs security threat pattern data using a threat feature identification unit.
[0055] The protection algorithm matching module receives the security threat pattern data, calls the protection algorithm library through the algorithm matching decision unit, and generates target security protection algorithm data using the optimization search unit.
[0056] The security protection execution module integrates the security zone division data, boundary protection configuration data, data exchange channel data, and target security protection algorithm data. It implements network security protection through the protection strategy execution unit and outputs network security status data through the status monitoring unit.
[0057] The strategy optimization module receives the network security status data, evaluates the system performance through the protection effectiveness analysis unit, generates optimized protection strategy data using the adaptive adjustment unit, and feeds it back to the boundary protection deployment module and the data exchange channel establishment module.
[0058] Compared with the prior art, the present invention provides a comprehensive ship network security protection system and method, which has the following beneficial effects:
[0059] 1. In this invention, by collecting and classifying data from ship computer systems, system classification data is generated, and network security area division is performed based on this data. This ensures the clarity of ship computer system classification and the rationality of network security area division, and implements differentiated security protection for different types of systems, thereby improving the orderliness and effectiveness of overall network security management.
[0060] 2. In this invention, boundary protection deployment is carried out by dividing data according to security zones, configuring firewall policies and network access control mechanisms, and establishing a dedicated data exchange channel to implement data transmission encryption and authentication. This enhances the access control capabilities of the network boundary and the reliability of data transmission, prevents unauthorized access, ensures the security of data exchange, and reduces the risk of network attacks.
[0061] 3. In this invention, a dynamic threat assessment matrix is constructed through real-time network traffic monitoring, an intelligent optimization algorithm is used to match the optimal security protection strategy, and the effectiveness of the protection strategy is analyzed and dynamically adjusted based on the network security status assessment report, so as to achieve adaptive security protection, respond to network threats in real time and optimize the protection strategy, thereby improving the accuracy and continuous improvement capability of network security protection. Attached Figure Description
[0062] Figure 1 This is a flowchart of a comprehensive ship network security protection method according to the present invention;
[0063] Figure 2 This is a schematic diagram of the architecture of a comprehensive ship network security protection system according to the present invention. Detailed Implementation
[0064] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0065] Specific embodiment: A comprehensive ship network security protection system and method, the method including:
[0066] S1. Collect data from the ship's computer system and classify it to generate system classification data;
[0067] S2. Based on the system classification data, perform network security zone division processing to generate security zone division data;
[0068] S3. Based on the security zone division data, perform boundary protection deployment processing, configure firewall policies and network access control mechanisms, and generate boundary protection configuration data;
[0069] S4. Based on the security zone division data and boundary protection configuration data, and combined with the characteristics of ship network communication needs, establish a dedicated data exchange channel and implement data transmission encryption authentication to generate data exchange channel data;
[0070] S5. Obtain current network security status information through real-time network traffic monitoring, construct a dynamic threat assessment matrix based on security zone division data, boundary protection configuration data and data exchange channel data, and use intelligent optimization algorithms to match the optimal security protection strategy to generate target security protection algorithm data.
[0071] S6. Integrate security zone division data, boundary protection configuration data, data exchange channel data, and target security protection algorithm data, and perform full lifecycle network security protection operations through the ship network monitoring platform to generate a network security status assessment report.
[0072] S7. Analyze the effectiveness of protection strategies based on the network security status assessment report, dynamically adjust the boundary protection strategy and data exchange channel parameters, generate optimized protection strategy data, and update it to the ship network monitoring platform.
[0073] Collecting and classifying data from the ship's computer system includes the following steps:
[0074] S11. Collect functional parameters of the ship's computer system through the ship network monitoring platform, including system name, function description, communication protocol type and physical location information;
[0075] S12. Classify ship computer systems according to the standards of the International Association of Classification Societies (IACS), dividing the systems into categories such as safety systems, communication and navigation systems, mechanical systems, engineering operation systems, cargo management systems, ship office management systems, crew and passenger entertainment systems, and wireless communication equipment, and generate system classification data.
[0076] S13. Standardize the system classification data with coding to ensure that each system category has a unique identifier;
[0077] First, a unique identifier is generated using a hash function. Then, the system category name and function description are hashed using the SHA-256 algorithm to generate a fixed-length code. The hashing process can be represented by the formula:
[0078] ;
[0079] in This represents the output 256-bit hash value. The input system classification data is then processed. Next, the hash value is standardized and pruned, with the first eight hexadecimal characters used as the identifier prefix. This prefix is then combined with the system type code to form the complete identifier, formatted as "type code-hash prefix". For example, the identifier for a security system class is "SEC-A1B2C3D4". Finally, these identifiers are stored in a database with an index table for easy data integration and retrieval. During implementation, the uniqueness of the encoding must be verified to prevent duplication, and the compliance of the identifier format must be validated using regular expressions.
[0080] The network security zone partitioning process includes the following steps:
[0081] S21. Obtain system classification data and combine it with the ship's physical space distribution information, including deck area, engine room area, bridge and crew living area, to make a preliminary division of network security areas;
[0082] S22. In accordance with the unified requirements of international classification societies, the initially defined areas will be further refined:
[0083] Safety system equipment is separately classified into the ship safety system area; communication and navigation system equipment is classified into the ship communication and navigation system area; mechanical system equipment is classified into the ship mechanical system area; engineering operation and cargo management equipment is classified into the cargo and engineering system area; wireless communication equipment is classified into the wireless equipment area; office management systems are classified into the management system area; and entertainment systems and uncertified systems are classified into other network areas.
[0084] S23. Generate security zone division data, including zone number, zone name, list of applicable systems and physical boundary description.
[0085] Border protection deployment and processing include the following steps:
[0086] S31. Based on the data divided into security zones, deploy industrial-grade firewall devices at the boundary of each security zone and configure port-based access control policies, including prohibiting unnecessary external access, restricting communication protocol types, and monitoring data traffic.
[0087] S32. Develop software protection strategies, including regularly updating operating system patches and implementing network access control technology to authenticate and check the security status of access devices;
[0088] S33. Verify the boundary protection configuration and generate boundary protection configuration data;
[0089] By simulating network attack scenarios—port scanning, unauthorized access attempts, and malicious data injection—the response capabilities of perimeter protection devices are tested. Simultaneously, testing tools are used to verify whether the network access control mechanism can correctly authenticate the identity of access devices and check their security status: verifying the validity of digital certificates and MAC address bindings. After verification, perimeter protection configuration data is generated, including test reports, policy effectiveness status, and any necessary adjustment records, providing a foundation for establishing subsequent data exchange channels.
[0090] Generating data exchange channel data includes the following steps:
[0091] S41. Based on the security zone division data and boundary protection configuration data, analyze the communication requirements between each zone, including data volume, real-time requirements and reliability indicators;
[0092] S42. Select the data exchange channel topology according to communication requirements, including star topology, ring topology and redundant tree topology, and use fiber optic communication technology and industrial Ethernet technology to construct the channel.
[0093] S43. Implement data transmission security measures, including using the AES encryption algorithm to encrypt data, establishing a two-way identity authentication mechanism based on digital certificates, and generating data exchange channel data;
[0094] The AES encryption algorithm uses a 256-bit key mode, and the encryption process can be represented by the formula:
[0095] ;
[0096] in Represents plaintext data. This indicates a 256-bit key. This represents the AES encryption function. This represents encrypted data;
[0097] The decryption process is the reverse:
[0098] ;
[0099] in This represents the AES decryption function;
[0100] Key management uses a key exchange protocol to periodically update keys, avoiding the risks associated with static keys.
[0101] Two-way authentication mechanism is implemented based on digital certificates:
[0102] First, both the sending and receiving ends possess X.509 format certificates, which are exchanged and signatures verified during authentication. The authentication process includes a challenge-response step: the sending end generates a random number and signs it with its private key; the receiving end verifies the signature using the sending end's public key and then replies with its own signed random number. A communication channel can only be established after successful two-way authentication. The entire mechanism is integrated into the protocol stack of the data exchange channel to ensure real-time encryption and authentication.
[0103] Generating target security protection algorithm data includes the following steps:
[0104] S51. Establish a database of standard security threat patterns corresponding to different security protection algorithms, represented as a matrix:
[0105] ;
[0106] in For a matrix, Indicates the first Standard security threat pattern data corresponding to each type of security protection algorithm. This represents the maximum number of security protection algorithm types.
[0107] S52. Match the real-time collected network traffic data with the standard security threat pattern database, and use artificial intelligence optimization algorithms to search for the optimal protection algorithm type to generate target security protection algorithm data.
[0108] The artificial intelligence optimization algorithm adopts the biomimetic osprey algorithm, which specifically includes the following sub-steps:
[0109] S521. Initialize algorithm parameters, including maximum number of iterations, population size, and search space boundary;
[0110] The initial population position, the position vector of each individual is represented as:
[0111] ;
[0112] in Indicates the first Individual ospreys Position vector in 3D space This represents the lower boundary vector of the search space. This represents the upper boundary vector of the search space. This represents a random number that is uniformly distributed within the interval [0,1].
[0113] S522, Exploration Phase: Simulate the ospreys randomly detecting the location of threat patterns, update the population location, and evaluate fitness values;
[0114] The formula for updating individual location is:
[0115] ;
[0116] in This indicates the updated location of the individual osprey. This indicates the current globally optimal position. Indicates the oscillation factor;
[0117] Calculate fitness value:
[0118] Fitness ;
[0119] Where Fitness represents the fitness value. The first element representing the real-time security threat feature vector One portion, This indicates the first in the standard threat pattern library. The first threat pattern Each feature component Represents the total dimension of the feature vector
[0120] S523, Development Phase: Simulate osprey hunting behavior, calculate new locations, and optimize matching results;
[0121] Generate new candidate positions around the current optimal position:
[0122] ;
[0123] in This indicates the location of the individual Osprey after the update during the development phase. This represents the position vector of the optimal solution in the current iteration. Indicates the current iteration number;
[0124] S524. Iterate until the termination condition is met, and output the security protection algorithm type that best matches the real-time data.
[0125] Generating a network security status assessment report includes the following steps:
[0126] S61. Combine and encapsulate the security zone division data, boundary protection configuration data, data exchange channel data, and target security protection algorithm data to construct a security protection summary data.
[0127] S62. The ship network monitoring platform calls the corresponding protection program based on the target security protection algorithm data to perform real-time monitoring and protection processing of network traffic;
[0128] The platform first parses the algorithm identifier and parameter configuration in the target security protection algorithm data: when the algorithm type is "Intrusion Detection System (IDS)," it calls the pre-compiled IDS dynamic link library (DLL); the calling process is implemented through the API interface: the GetProcAddress function is used to load the protection function in the DLL and pass in the parameters; after the protection program is executed, it returns the detection result, and the platform triggers a response action based on the result; to ensure robustness, the program signature and hash value must be verified before the call to prevent malicious code injection; at the same time, a timeout mechanism is set to avoid program freeze affecting real-time performance;
[0129] S63. Generate network security status data, including threat logs, protection effectiveness assessments, and system health indicators.
[0130] Generating optimized protection strategy data and updating it to the ship network monitoring platform includes the following steps:
[0131] S71. Based on network security status data, conduct protection strategy effectiveness analysis and identify weaknesses;
[0132] The effectiveness analysis employs a multi-index fusion method to calculate the comprehensive effectiveness value of the protection strategy, expressed by the formula:
[0133] ;
[0134] in This represents the overall effectiveness value of the protection strategy. Indicates the number of indicators. Indicates the first The normalized value of each indicator. Indicates the first The weight of each indicator;
[0135] During the analysis, log data is extracted from network security status data, the actual values of each indicator are calculated, and then substituted into the formula to obtain E. When E is lower than the threshold, the policy effectiveness is determined to be insufficient, and the weak link is located. The analysis results generate an effectiveness report for policy optimization reference.
[0136] S72. Adaptive learning algorithms are used to dynamically adjust the boundary protection strategy and data exchange channel parameters;
[0137] The adaptive learning algorithm uses the Q-learning algorithm, whose core formula is:
[0138] ;
[0139] in Indicates the state Take action below Q value, Indicates an immediate reward. Indicates the learning rate. Indicates the discount factor. Indicates the next state. Indicates the state The following actions may be taken. Indicates the maximum expected payoff for the next state;
[0140] During implementation, the algorithm learns the optimal strategy from historical data: state data is collected every hour, reward values are calculated, and the Q-table is updated. Subsequently, actions are selected based on the Q-table, and parameters are dynamically adjusted: bandwidth limitations of the data exchange channel are relaxed;
[0141] S73. Generate optimized protection strategy data and update it to the ship network monitoring platform.
[0142] The system includes a ship system data acquisition module, a security zone division module, a boundary protection deployment module, a data exchange channel establishment module, a security threat detection module, a protection algorithm matching module, a security protection execution module, and a strategy optimization module.
[0143] The ship system data acquisition module collects the ship computer system operating parameters through the ship network data acquisition unit and generates system classification data using the system classification processing unit.
[0144] The security zone division module receives the system classification data, determines the network security zone boundary through the zone logical division unit, and outputs the security zone division data using the zone attribute configuration unit.
[0145] The boundary protection deployment module receives the security zone division data, deploys hardware protection devices through the firewall policy configuration unit, and generates boundary protection configuration data using the security policy loading unit.
[0146] The data exchange channel establishment module receives the security zone division data and boundary protection configuration data, designs the data exchange path through the channel topology construction unit, and generates data exchange channel data using the secure transmission protocol unit.
[0147] The security threat detection module collects network data streams through the real-time traffic monitoring unit and outputs security threat pattern data using the threat feature identification unit.
[0148] The protection algorithm matching module receives the security threat pattern data, calls the protection algorithm library through the algorithm matching decision unit, and generates target security protection algorithm data using the optimization search unit.
[0149] The security protection execution module integrates the security zone division data, boundary protection configuration data, data exchange channel data, and target security protection algorithm data. It implements network security protection through the protection strategy execution unit and outputs network security status data through the status monitoring unit.
[0150] The strategy optimization module receives the network security status data, evaluates the system performance through the protection effectiveness analysis unit, generates optimized protection strategy data using the adaptive adjustment unit, and feeds it back to the boundary protection deployment module and the data exchange channel establishment module.
[0151] The operating steps of this system and method are as follows:
[0152] First, data from the ship's computer system is collected and classified to generate system classification data. Then, based on the system classification data, network security zones are divided to generate security zone division data. Subsequently, based on the security zone division data, boundary protection deployment is carried out, firewall policies and network access control mechanisms are configured to generate boundary protection configuration data.
[0153] Based on this, and using security zone division data and boundary protection configuration data, combined with the characteristics of ship network communication needs, a dedicated data exchange channel is established and data transmission encryption and authentication are implemented to generate data exchange channel data. Real-time network traffic monitoring is used to obtain current network security status information. Based on security zone division data, boundary protection configuration data, and data exchange channel data, a dynamic threat assessment matrix is constructed. Intelligent optimization algorithms are used to match the optimal security protection strategy to generate target security protection algorithm data.
[0154] Finally, by integrating security zone division data, boundary protection configuration data, data exchange channel data, and target security protection algorithm data, the ship network monitoring platform performs full lifecycle network security protection operations and generates a network security status assessment report. Based on the network security status assessment report, the effectiveness of protection strategies is analyzed, boundary protection strategies and data exchange channel parameters are dynamically adjusted, optimized protection strategy data is generated, and updated back to the ship network monitoring platform, thereby achieving continuous adaptive protection of ship network security.
[0155] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0156] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A method of ship cyber security protection, characterized by: The method comprises: S1, collecting ship computer system data and classifying processing to generate system classification data; S2, performing network security region division processing based on the system classification data to generate security region division data; S3, performing boundary protection deployment processing according to the security region division data, configuring firewall policy and network access control mechanism, and generating boundary protection configuration data; S4, based on the security region division data and the boundary protection configuration data, combining with the ship network communication demand characteristics, establishing a data exchange special channel and implementing data transmission encryption authentication, and generating data exchange channel data; The generation of data exchange channel data comprises the following steps: S41, based on the security region division data and the boundary protection configuration data, analyzing the communication demand between regions, including data volume, real-time requirement and reliability index; S42, selecting data exchange channel topology according to the communication demand, including star topology, ring topology and redundant tree topology, and using optical fiber communication technology and industrial Ethernet technology to construct the channel; S43, implementing data transmission security measures, including using AES encryption algorithm to encrypt the data, establishing a two-way identity authentication mechanism based on digital certificate, and generating data exchange channel data; S5, obtaining current network security state information through real-time network flow monitoring, constructing a dynamic threat evaluation matrix based on the security region division data, the boundary protection configuration data and the data exchange channel data, adopting intelligent optimization algorithm to match the optimal security protection strategy, and generating target security protection algorithm data; S6, integrating the security region division data, the boundary protection configuration data, the data exchange channel data and the target security protection algorithm data, executing the whole life cycle network security protection operation through the ship network supervision platform to generate a network security state evaluation report; S7, performing protection strategy effectiveness analysis according to the network security state evaluation report, dynamically adjusting the boundary protection strategy and the data exchange channel parameters, generating optimized protection strategy data and feeding back to the ship network supervision platform.
2. The method of claim 1, wherein: The collection of ship computer system data and the classification processing comprise the following steps: S11, collecting the function parameters of the ship computer system through the ship network supervision platform, including system name, function description, communication protocol type and physical location information; S12, classifying processing the ship computer system according to the international ship classification society association standard, dividing the system into safety system class, communication and navigation system class, mechanical system class, engineering operation system class, cargo management system class, ship office management system class, crew and passenger entertainment system class and wireless communication equipment class, and generating system classification data; S13, standardizing coding processing the system classification data to ensure that each system category has a unique identifier.
3. The method of claim 2, wherein: The network security region division processing comprises the following steps: S21, obtaining the system classification data, combining with the ship physical space distribution information including deck area, engine room area, bridge and crew living area, and performing preliminary network security region division; S22, according to the unified requirements of international ship classification societies, the preliminarily divided regions are finely adjusted: The safety system class equipment is independently divided into the ship safety system area, the communication and navigation system class equipment is divided into the ship communication and navigation system area, the mechanical system class equipment is divided into the ship mechanical system area, the engineering operation and cargo management class equipment is divided into the cargo and engineering system area, the wireless communication equipment is divided into the wireless equipment area, the office management class system is divided into the management system area, and the entertainment system and the unauthenticated system are divided into the other network area; S23, safety area division data is generated, including region number, region name, applicable system list and physical boundary description.
4. The method of claim 3, wherein: The boundary protection deployment process comprises the following steps: S31, according to the safety area division data, industrial-grade firewall equipment is deployed at the boundary of each safety area, and a port-based access control strategy is configured, including prohibiting unnecessary external access, limiting communication protocol types and data flow monitoring; S32, a software protection strategy is formulated, including regularly updating operating system patches, implementing network access control technology to authenticate access equipment and check the security state; S33, the boundary protection configuration is verified, and boundary protection configuration data is generated.
5. The method of claim 4, wherein: The target security protection algorithm data is generated, comprising the following steps: S51, a standard security threat mode database corresponding to different security protection algorithms is established, which is represented by a matrix as follows: ; wherein is a matrix, represents the standard security threat mode data corresponding to the kind of security protection algorithm type, represents the maximum value of the number of security protection algorithm types. S52, the real-time collected network traffic data is matched with the standard security threat mode database, and the optimal protection algorithm type is searched through an artificial intelligence optimization algorithm to generate target security protection algorithm data.
6. The method of claim 5, wherein: The artificial intelligence optimization algorithm adopts a bionic fish-eagle algorithm, which specifically comprises the following sub-steps: S521, initialize algorithm parameters, including maximum iteration number, population size and search space boundary; S522, exploration stage: simulate fish eagles to randomly detect threat mode positions, update population positions and evaluate fitness values; S523, development stage: simulate fish eagles hunting behavior, calculate new positions and optimize matching results; S524, iterate until the termination condition is met, and output the security protection algorithm type that best matches the real-time data.
7. The method of claim 6, wherein: The network security state evaluation report is generated, comprising the following steps: S61, the safety area division data, boundary protection configuration data, data exchange channel data and target security protection algorithm data are combined and packaged to construct security protection summary data; S62, the ship network supervision platform calls the corresponding protection program according to the target security protection algorithm data to perform real-time monitoring and protection processing on network traffic; S63, network security state data is generated, including threat logs, protection effect evaluation and system health degree index.
8. The method of claim 7, wherein: The optimized protection strategy data is generated and fed back to the ship network supervision platform, comprising the following steps: S71, based on the network security state data, perform protection strategy efficiency analysis to identify weak links; S72, dynamically adjust the boundary protection strategy and data exchange channel parameters using an adaptive learning algorithm; S73, generate optimized protection strategy data and update to the ship network supervision platform.
9. A ship integrated cyber security protection system for implementing a ship integrated cyber security protection method according to any one of claims 1-8, characterized by: The system comprises a ship system data acquisition module, a security area division module, a boundary protection deployment module, a data exchange channel establishment module, a security threat detection module, a protection algorithm matching module, a security protection execution module and a strategy optimization module; The ship system data acquisition module acquires ship computer system operation parameters through a ship network data acquisition unit and generates system classification data using a system classification processing unit; The security area division module receives the system classification data, determines network security area boundaries through a region logical division unit and outputs security area division data using a region attribute configuration unit; The boundary protection deployment module receives the security area division data, deploys a hardware protection device through a firewall policy configuration unit and generates boundary protection configuration data using a security policy loading unit; The data exchange channel establishment module receives the security area division data and boundary protection configuration data, designs a data exchange path through a channel topology construction unit and generates data exchange channel data using a secure transmission protocol unit; The security threat detection module acquires network data flow through a real-time flow monitoring unit and outputs security threat mode data using a threat feature recognition unit; The protection algorithm matching module receives the security threat mode data, calls a protection algorithm library through an algorithm matching decision unit and generates target security protection algorithm data using an optimization search unit; The security protection execution module integrates the security area division data, boundary protection configuration data, data exchange channel data and target security protection algorithm data, implements network security protection through a protection policy execution unit and outputs network security state data using a state monitoring unit; The strategy optimization module receives the network security state data, evaluates system performance through a protection efficiency analysis unit, generates optimized protection strategy data using an adaptive adjustment unit and feeds back to the boundary protection deployment module and the data exchange channel establishment module.
Citation Information
Patent Citations
Ship law enforcement-oriented sea area safety early warning method
CN118411856A
Ship control cabinet network security protection method and system
CN120498771A